OVERVIEW CVE-2026-35033 is an unauthenticated arbitrary file read vulnerability affecting Jellyfin media server versions prior to 10.11.7. The flaw exists in the StreamOptions query parameter parsing mechanism, where unsanitized user input is concatenated directly into ffmpeg command-line arguments. An attacker can inject a drawtext filter with a textfile argument to read sensitive server files such as /etc/shadow and exfiltrate their contents through the video stream response. SEVERITY This vulnerability carries a CVSS score of 9.1 (CRITICAL) with a network-based attack vector requiring no authentication or user interaction and low attack complexity. The primary impact is confidentiality breach, as attackers can read arbitrary files on the affected server. The attack does require knowledge of valid item GUIDs, which typically necessitates prior authenticated access to enumerate, though this is a secondary barrier to exploitation. EXPLOITATION STATUS The vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no evidence of active exploitation in the wild, with an exceptionally low EPSS score of 0.00144. However, no indicators suggest exploit code is unavailable or that the security community has limited awareness of the issue. Organizations running Jellyfin should prioritize patching to version 10.11.7 or later to eliminate this critical remote file access risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.11.7CPE matchmatch criteria | cpe:2.3:a:jellyfin:jellyfin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.